Meridian Manufacturing Ltd. is a large, multidivisional Singapore-based manufacturer of electronic components and products. Over the past

Question:

Meridian Manufacturing Ltd. is a large, multidivisional Singapore-based manufacturer of electronic components and products. Over the past few years, Meridian has progressively implemented local area networks throughout its divisions. Currently, eight local area networks exist. Each can communicate with the others through bridges installed in their file servers. All local area networks also provide the platform for accounting information systems that are material from the viewpoint of Meredian's financial statements.

You are an information systems auditor in a firm of certified public accountants that has just taken over the external audit of Meridian. The partner in charge of the audit asks you to examine controls over the local area networks. You encounter the following situations during your investigations:

1. The file servers supporting the eight local area networks sit on a long desk outside Meredian's mainframe computer room. When you point out to the operations manager that you are concerned about the security of the file servers, she retorts that access to the information system facilities is restricted to information systems staff. In addition, she informs you that the file-server keyboards are locked via a password. The keyboards can be unlocked only if the correct password is first keyed in to the file server.

2. One of the local area networks in an engineering division provides a gateway to a public wide area network. When you ask the divisional manager about the purposes of the gateway, he informs you that his staff uses the gateway to exchange electronic mail with their colleagues in other companies and in several research institutes. In addition, they sometimes exchange software and data files that they have found helpful in their jobs.

3. Maintenance of the local area networks is undertaken under contract by a small firm that specializes in selling and supporting local area networks for manufacturing organizations. The operations manager comments that she is very happy with the service provided by the person who undertakes the maintenance work. The networks have very little downtime. Moreover, the person who undertakes maintenance work is happy to work on the networks after hours so that disruption to network users is minimized.

4. When you ask the operations manager about future plans for the networks, she informs you that the person who undertakes maintenance periodically makes recommendations about how the networks should be reconfigured and expanded. He has several utilities that he employs to monitor network usage, and in the past he has provided timely information on new hardware and software that should be purchased to support the networks.

Required. From the viewpoint of the external audit, do any of the situations described here constitute exposures? If so, write a brief report for the partner in charge of the audit informing him how the situation constitutes an exposure and what controls should be implemented to eliminate the exposure or to reduce expected losses from the exposure to an acceptable level. In addition, provide suggestions on how the conduct of the remainder of the audit should be modified in light of your concerns.

Fantastic news! We've Found the answer you've been seeking!

Step by Step Answer:

Related Book For  book-img-for-question
Question Posted: